CVE-2021-20190 is a high-severity deserialization vulnerability in FasterXML jackson-databind versions prior to 2.9.10.7, affecting products from vendors like Apache, Debian, NetApp, and Oracle. This flaw, categorized as CWE-502, arises from mishandling interactions between serialization gadgets and typing. With a CVSS score of 8.1 (HIGH), it presents a significant risk to data confidentiality, integrity, and system availability, requiring high attack complexity but no user interaction or prior authentication. Despite its severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.7.5CPE matchmatch criteria | cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | ||
>= 2.7.0, < 2.9.10.7CPE matchmatch criteria | cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_api_services:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025
Aug 6, 2025Deserialization of untrusted data in jackson-databind
Jan 20, 2021jackson-databind: mishandles the interaction between serialization gadgets and typing, related to javax.swing
Jan 16, 2021